Showing 36 of 59 projects
A tool for secrets management, encryption as a service, and privileged access management.
A tool for securely accessing secrets, providing encryption as a service, and managing privileged access.
A curated list of tools and resources for digital forensics and incident response (DFIR) teams.
A static analysis tool that scans Go source code for security vulnerabilities by analyzing the AST and SSA representations.
An automated cyber security platform for adversary emulation, red teaming, and incident response built on the MITRE ATT&CK framework.
An open-source adversary emulation platform that simulates malware attacks to test and improve network security defenses.
A modular reconnaissance framework for conducting open source intelligence (OSINT) gathering from web-based sources.
A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.
An open-source security automation platform (SOAR) built for security professionals, focusing on collaboration and resource sharing.
Automatically generate least-privilege IAM policies for AWS based on resource ARNs and access levels.
Automatically generate least-privilege IAM policies for AWS by specifying resource ARNs and access levels.
Monitor GitHub for sensitive information leaks in near real-time and send alert notifications.
A command-line tool that automates password cracking methodologies through Hashcat with integrated wordlist management and attack orchestration.
A modular PowerShell framework for enterprise incident response and breach hunting using remote data collection.
A modular PowerShell framework for enterprise incident response and breach hunting using remote data collection.
An automated phishing email analysis tool that extracts observables, integrates with TheHive/Cortex/MISP, and calculates verdicts.
A command-line tool to securely configure macOS security and privacy settings with a single command.
A security feed collection and processing solution for IT security teams using message queuing protocols.
A curated awesome list of resources for Security Orchestration, Automation and Response (SOAR) technologies.
A curated collection of public JSON APIs for cybersecurity professionals, covering threat intelligence, malware analysis, and security tools.
A professional-grade web security scanner for penetration testing with intelligent, context-aware scanning and proof-based vulnerability detection.
An extendable Python tool to extract and aggregate Indicators of Compromise (IOCs) from various threat intelligence feeds.
An extendable Python tool to extract and aggregate Indicators of Compromise (IOCs) from various threat intelligence feeds.
Embed dependency information into Rust binaries for vulnerability auditing in production.
A tool to gather and enrich threat intelligence indicators from publicly available sources into a structured CSV format.
A framework for executing and detecting cloud attacker TTPs via YAML definitions, generating APIs, Sigma rules, and documentation.
A Python library and CLI for extracting and refanging defanged Indicators of Compromise (IOCs) from text.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
Default playbooks and custom functions for Splunk SOAR (formerly Phantom) security orchestration and automation platform.
A self-hosted incident response platform that automates alert handling and ticket management for security teams.
A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.
A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.
A security tool for AWS that enforces resource ownership, detects domain hijacking, and verifies security services.
A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.